Alureon.h

Fermé
blueway - 15 mai 2010 à 06:20
 blueway - 22 mai 2010 à 19:54
Bonjour à tous,

depuis 2 jours, j'ai quelques pb avec IE8 ... macafee ne détecte rien, spyware doctor non plus, mais un live scan one care de microsoft m'indique la présence de WIN32/Alureon.h
Existe t'il un moyen de s'en débarasser ?
Merci d'avance.
Daniel



30 réponses

plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
16 mai 2010 à 11:25
salut

jme permet d'intervenir car je suivais deja ce sujet est malheureusement ce rootkit patch des fichier systemes

Blueway poste ce rapport

C:/combofix.txt et celui de TDSS remover stp
2
Karel7 Messages postés 709 Date d'inscription mardi 11 mai 2010 Statut Contributeur Dernière intervention 2 octobre 2019 58
15 mai 2010 à 21:45
Salut,
Ah le PC :s ...
Voyons ce qu'il y a :

*Télécharge http://images.malwareremoval.com/random/RSIT.exe Random's System Information Tool (RSIT) de Random/Random, et enregistre le sur ton Bureau.
*Sous Windows 7 : Suivre ce tutoriel https://www.androidworld.fr/ pour rendre RSIT compatible avec Windows 7.
* Ensuite double clique sur RSIT.exe pour lancer l'outil.
* Clique sur "Continue" à l'écran Disclaimer.
*Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence.
*Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

Tutoriel illustré pour t'aider : https://www.androidworld.fr/

https://www.androidworld.fr/ Comment héberger les rapports trop longs de RSIT

++
1
Bonjour Nydarion,
merci pour l'aide, je fais cela de suite.
A+
0
Bon ben ça tourne encore .... patience ;-)
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Nydarion Messages postés 155 Date d'inscription mercredi 12 mai 2010 Statut Membre Dernière intervention 23 novembre 2010 7
15 mai 2010 à 11:00
un EXPERT vous guidera pour la suite....

@+
0
Voilà le résultat

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Version de la base de données: 4103

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

15/05/2010 11:01:21
mbam-log-2010-05-15 (11-01-21).txt

Type d'examen: Examen complet (C:\|D:\|)
Elément(s) analysé(s): 441905
Temps écoulé: 4 heure(s), 12 minute(s), 33 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 1
Fichier(s) infecté(s): 3

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> No action taken.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\FLV Direct Player (Adware.BHO.FL) -> No action taken.

Fichier(s) infecté(s):

Merci
0
Nydarion Messages postés 155 Date d'inscription mercredi 12 mai 2010 Statut Membre Dernière intervention 23 novembre 2010 7
Modifié par Nydarion le 15/05/2010 à 11:18
No action taken. tu dois Supprimer la sélection...normalement tu dois voir Quarantined and deleted successfully.
0
j'ai lancé la suppression et ensuite mon PC a rebooté ... écran bleu puis mode sans echec ... impossible de me loguer, alors je suis reparti en mode normal avec derniere bonne config, et là c'est parti mais ça mouline sur écran noir depuis 2heures. je vous écris d'un autre pc
any idea ?
0
Hello merci pour l'aide,
j'ai finalement réussi à le redémarrer.
Toutefois j'ai encore des fenêtres bizarres qui s'ouvrent prpoposant un scan de mon PC ....
Je n'ai pas de graveur de CD donc il faut que j'aille ailleurs....
Existe il un autre moyen ?
Merci d'avance pour le temps passé ;-)
0
Quelques nouvelles:
Microsoft one care live me sort la même erreur.
Je n'ai plus accès à Windows update.
J'ai téléchargé la version free de Avira, mise à jour et je l'ai lancée ... j'attends.
Merci d'avance.
0
Bonjour,
après une longue nuit ...
J'ai lancé Combofix, puis TDDS Remover, puis re Combofix.

Pb résolu !

Avira, clean
Macafee clean
Microsoft one care live .... clean

Karel et Nydarion : MERCI
0
Karel7 Messages postés 709 Date d'inscription mardi 11 mai 2010 Statut Contributeur Dernière intervention 2 octobre 2019 58
16 mai 2010 à 11:11
Salut
Attention si tu garde plus d'un antivirus en même temps, choisi un SEUL et supprime les autres (conseil : Avira)
Et puis, si tu n'a pas analysé tes rapports ... en plus qu'on utilise pas ces outils sans une demande par une personne qualifiée !!
Alors je crois que tu dois quand même poster un rapport RSIT puisqu'il n'est vraiment pas sur que ton PC soit vraiment clean

++
0
Karel7 Messages postés 709 Date d'inscription mardi 11 mai 2010 Statut Contributeur Dernière intervention 2 octobre 2019 58
16 mai 2010 à 12:01
Salut,

Bon ... tu te debrouillera mieux que moi Plopus, je te laisse faire :)

++
0
Désolé les amis,
j'étais en mission pour 3 jours je viens de rentrer.
Oulala ... vous me fichez la trouille ... bon je suis blonde mais n'en profitez pas ;-)
Le COMBOFIX est en cours de préparation ;-)

Merci à vous
0
Voilà le rapport RSIT

Logfile of random's system information tool 1.07 (written by random/random)
Run by DMartiano at 2010-05-20 16:52:58
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 29 GB (45%) free of 64 GB
Total RAM: 3032 MB (53% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:53:28, on 20/05/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\WINDOWS\system32\DTS.exe
C:\windows\system32\ibmpmsvc.exe
C:\WINDOWS\system32\AtService.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\windows\system32\brsvc01a.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\brss01a.exe
D:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
C:\windows\system32\svchost.exe
C:\windows\System32\TPHDEXLG.exe
C:\Program Files\Fichiers communs\Intel\Privacy Icon\UNS\UNS.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe
C:\windows\system32\TpShocks.exe
C:\WINDOWS\vsnp2uvc.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\windows\system32\rundll32.exe
C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\windows\system32\SearchIndexer.exe
C:\windows\system32\igfxext.exe
C:\windows\system32\igfxsrvc.exe
C:\windows\System32\svchost.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE
D:\Program Files\Avira\AntiVir Desktop\avcenter.exe
C:\windows\explorer.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
D:\Program Files\Avira\AntiVir Desktop\avscan.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\DMARTIANO\Bureau\Outils\CLEAN\RSIT.exe
C:\windows\system32\SearchProtocolHost.exe
C:\Program Files\trend micro\DMartiano.exe
0
======Scheduled tasks folder======

C:\windows\tasks\PCDoctorBackgroundMonitorTask.job
C:\windows\tasks\PMTask.job
C:\windows\tasks\Vérifier les mises à jour de Windows Live Toolbar.job
C:\windows\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-04-02 61888]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0F3D1B-0909-4FF4-B272-609CCE6054E7}]
PC Tools Browser Guard BHO - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll [2006-11-30 67136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6}]
Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 546672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BF468356-BB7E-42D7-9F15-4F3B9BCFCED2}]
IePasswordManagerHelper Class - C:\Program Files\Lenovo\Client Security Solution\tvtpwm_ie_com.dll [2008-06-13 808248]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-09-17 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-09-17 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-21 368640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - Windows Live Toolbar - C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 546672]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-21 368640]
{9421DD08-935F-4701-A9CA-22DF90AC4EA6} - Easy Photo Print - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2008-04-02 266240]
{472734EA-242A-422B-ADF8-83D1E48CC825} - PC Tools Browser Guard - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll [2010-01-22 567248]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"TPFNF7"=C:\PROGRA~1\Lenovo\NPDIRECT\TPFNF7SP.exe [2009-01-07 60704]
"TpShocks"=C:\windows\system32\TpShocks.exe [2009-02-02 181536]
"snp2uvc"=C:\WINDOWS\vsnp2uvc.exe [2006-12-28 569344]
"TPHOTKEY"=C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe [2008-09-30 68976]
"EZEJMNAP"=C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe [2008-10-08 256576]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2008-03-07 167936]
"FingerPrintSoftware"=C:\Program Files\Lenovo Fingerprint Software\fpapp.exe [2009-03-19 12095488]
"CameraApplicationLauncher"=C:\Program Files\Lenovo\Camera Center\bin\CameraApplicationLaunchpadLauncher.exe [2008-08-12 16384]
"PWRMGRTR"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor []
"BLOG"=rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog []
"TrackPointSrv"=C:\Program Files\Lenovo\TrackPoint\tp4serv.exe [2009-01-26 92960]
"picon"=C:\Program Files\Fichiers communs\Intel\Privacy Icon\PrivacyIconClient.exe [2009-02-12 357400]
"ShStatEXE"=C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [2006-11-30 112216]
"McAfeeUpdaterUI"=C:\Program Files\McAfee\Common Framework\UdaterUI.exe [2006-11-17 136768]
"EEventManager"=C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe [2009-01-12 669520]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SAIICpl.exe [2009-11-19 307768]
"avgnt"=D:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"QuickTime Task"=D:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"=D:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]
"ctfmon.exe"=C:\windows\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe [2010-03-24 952768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2010-04-02 40368]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
D:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2009-11-15 33120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMSG]
C:\Program Files\ThinkVantage\AMSG\Amsg.exe [2007-02-01 419376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BrowserChoice]
C:\windows\system32\browserchoice.exe [2010-02-12 293376]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreateLMBCShortCut]
C:\Program Files\Lenovo\Mobile Broadband Connect\UserShortcutCreator.exe [2009-01-21 36864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cssauth]
C:\Program Files\Lenovo\Client Security Solution\cssauth.exe [2008-06-13 3073336]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\windows\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM]
C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [2009-02-06 843776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
C:\windows\system32\hkcmd.exe [2008-10-30 178712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
C:\windows\system32\igfxtray.exe [2008-10-30 150040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPMailChecker]
C:\PROGRA~1\THINKV~1\PrdCtr\LPMLCHK.exe [2009-01-29 124248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager]
C:\PROGRA~1\THINKV~1\PrdCtr\LPMGR.exe [2009-01-29 185688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMServer]
C:\Program Files\Fichiers communs\Nokia\MPlatform\NokiaMServer /watchfiles startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaMusic FastStart]
C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe [2009-11-06 2090272]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
D:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2009-11-11 1451520]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
C:\windows\system32\igfxpers.exe [2008-10-30 150040]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
D:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-09-17 149280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPHELPER]
C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe [2007-01-09 868352]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
D:\Program Files\Trojan Remover\Trjscan.exe [2009-08-04 1068424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy]
C:\Program Files\Fichiers communs\Lenovo\Scheduler\scheduler_proxy.exe [2008-11-24 487424]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-03 204288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Acrobat Assistant.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Distillr\AcroTray.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
C:\PROGRA~1\ThinkPad\BLUETO~1\BTTray.exe [2008-03-28 596584]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Digital Line Detect.lnk]
C:\PROGRA~1\DIGITA~1\DLG.exe [2006-11-03 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Post-it® Software Notes Lite.lnk]
C:\PROGRA~1\3M\PSNLite\PsnLite.exe [2004-10-15 2080768]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^RCIMGDIR.exe.lnk]
C:\PROGRA~1\ROTATE~1\RCIMGDIR.exe [2008-06-12 31744]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^VPN Client.lnk]
C:\windows\Installer\{871DF2BE-41D2-4334-AC33-839AF16FC8FE}\Icon3E5562ED7.ico [2009-06-29 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2008-05-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"DWMRCS"=2
"SUService"=2
"stllssvr"=3
"StarWindServiceAE"=2
"sdCoreService"=3
"sdAuxService"=3
"SCardSvr"=2
"RoxMediaDB10"=3
"ProtexisLicensing"=2
"mnmsrvc"=3
"Microsoft Office Groove Audit Service"=3
"MDM"=3
"JavaQuickStarterService"=2
"COMSysApp"=2
"aspnet_state"=3
"WudfSvc"=2
"TVT Scheduler"=2
"TSSCoreService"=2
"ThinkVantage Registry Monitor Service"=3
"WMPNetworkSvc"=2
"TpKmpSVC"=2
"ADMonitor"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ATFUS]
C:\WINDOWS\system32\FpWinLogonNp.dll [2009-03-19 180224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\windows\system32\igfxdev.dll [2008-10-21 217088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tpfnf2]
C:\Program Files\Lenovo\HOTKEY\notifyf2.dll [2006-09-06 34344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tphotkey]
C:\Program Files\Lenovo\HOTKEY\tphklock.dll [2008-08-08 28672]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\windows\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdauxservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdcoreservice]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"HonorAutoRunSetting"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\McAfee\Common Framework\FrameworkService.exe"="C:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\TeamViewer\Version4\TeamViewer.exe"="C:\Program Files\TeamViewer\Version4\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
"C:\Program Files\Epson Software\Event Manager\EEventManager.exe"="C:\Program Files\Epson Software\Event Manager\EEventManager.exe:*:Disabled:EEventManager Application"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"D:\Program Files\uTorrent\uTorrent.exe"="D:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"D:\Program Files\CounterPath\X-Lite\x-lite.exe"="D:\Program Files\CounterPath\X-Lite\x-lite.exe:*:Enabled:X-Lite"
0
plopus Messages postés 5962 Date d'inscription jeudi 1 janvier 2009 Statut Contributeur sécurité Dernière intervention 11 mars 2012 293
20 mai 2010 à 18:15
slt


j'ai ecrit => Blueway poste ce rapport

C:/combofix.txt et celui de TDSS remover stp


de plus le rapport que tu poste n'est pas entier car trop long, tu le repostera en ^pasant par Cijoint => http://www.cijoint.fr/
0
======List of files/folders created in the last 1 months======

2010-05-20 16:52:59 ----D---- C:\Program Files\trend micro
2010-05-19 08:44:29 ----SHD---- C:\RECYCLER
2010-05-18 08:54:09 ----A---- C:\ComboFix.txt
2010-05-18 08:33:29 ----D---- C:\combofix
2010-05-18 08:29:01 ----D---- C:\Qoobox
2010-05-17 08:28:54 ----HDC---- C:\windows\ie8
2010-05-16 20:06:45 ----HDC---- C:\windows\$NtUninstallKB978542$
2010-05-16 20:01:50 ----HDC---- C:\windows\$NtUninstallKB979306$
2010-05-16 20:01:33 ----A---- C:\windows\imsins.BAK
2010-05-16 19:57:32 ----N---- C:\windows\system32\browserchoice.exe
2010-05-15 22:42:56 ----RASHD---- C:\cmdcons
2010-05-15 22:40:00 ----A---- C:\windows\NIRCMD.exe
2010-05-15 22:40:00 ----A---- C:\windows\MBR.exe
2010-05-15 22:39:56 ----A---- C:\windows\zip.exe
2010-05-15 22:39:56 ----A---- C:\windows\SWXCACLS.exe
2010-05-15 22:39:56 ----A---- C:\windows\SWSC.exe
2010-05-15 22:39:56 ----A---- C:\windows\SWREG.exe
2010-05-15 22:39:56 ----A---- C:\windows\sed.exe
2010-05-15 22:39:56 ----A---- C:\windows\PEV.exe
2010-05-15 22:39:56 ----A---- C:\windows\grep.exe
2010-05-15 22:38:38 ----D---- C:\windows\ERDNT
2010-05-15 19:01:10 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2010-05-15 06:42:31 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Malwarebytes
2010-05-15 06:42:18 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-05-15 06:42:17 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-05-15 06:27:27 ----D---- C:\Program Files\ZHPDiag
2010-05-14 22:51:04 ----N---- C:\windows\system32\MpSigStub.exe
2010-05-14 22:29:11 ----RAD---- C:\autorun.inf
2010-05-14 09:33:58 ----A---- C:\windows\monitor.INI
2010-05-14 08:18:49 ----D---- C:\Program Files\Lavasoft
2010-05-14 08:18:49 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-05-14 07:51:27 ----D---- C:\Program Files\Windows Live Safety Center
2010-05-14 00:23:52 ----D---- C:\windows\SoftwareDistribution
2010-05-13 23:47:51 ----A---- C:\windows\system32\ztvunrar36.dll
2010-05-13 23:47:51 ----A---- C:\windows\system32\ztvunace26.dll
2010-05-13 23:47:51 ----A---- C:\windows\system32\ztvcabinet.dll
2010-05-13 23:47:50 ----A---- C:\windows\system32\UNRAR3.dll
2010-05-13 23:47:50 ----A---- C:\windows\system32\unacev2.dll
2010-05-13 23:47:47 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Simply Super Software
2010-05-13 23:47:47 ----D---- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2010-05-13 23:22:31 ----D---- C:\rsit
2010-05-13 20:21:41 ----HD---- C:\windows\msdownld.tmp
2010-05-13 19:07:09 ----D---- C:\windows\SoftwareDistribution.old
2010-05-13 15:26:24 ----A---- C:\windows\SGDetectionTool.dll
2010-05-13 15:26:24 ----A---- C:\windows\PCTBDRes.dll
2010-05-13 15:26:24 ----A---- C:\windows\PCTBDCore.dll.old
2010-05-13 15:26:24 ----A---- C:\windows\PCTBDCore.dll
2010-05-13 15:26:24 ----A---- C:\windows\BDTSupport.dll.old
2010-05-13 15:26:24 ----A---- C:\windows\BDTSupport.dll
2010-05-13 15:13:46 ----D---- C:\Program Files\Spyware Doctor
2010-05-13 15:13:46 ----D---- C:\Program Files\Fichiers communs\PC Tools
2010-05-13 15:13:46 ----D---- C:\Documents and Settings\All Users\Application Data\PC Tools
2010-05-13 10:13:54 ----D---- C:\Program Files\DivX
2010-05-13 10:05:36 ----D---- C:\Documents and Settings\All Users\Application Data\DivX
2010-05-03 22:07:39 ----D---- C:\Program Files\Rallentando Software
2010-05-03 19:08:23 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Music Recognition
2010-04-30 18:46:24 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Thinstall
2010-04-28 00:39:54 ----A---- C:\windows\iun6002.exe
2010-04-27 22:25:13 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\REAPER
2010-04-27 22:08:38 ----A---- C:\windows\uninst.exe
2010-04-26 16:25:24 ----A---- C:\windows\DMN.INI
2010-04-26 16:24:38 ----D---- C:\Program Files\Yamaha Corporation
2010-04-26 13:41:07 ----A---- C:\windows\system32\VBHLP32.DLL
2010-04-26 13:41:06 ----A---- C:\windows\system32\VBALNCSM6.DLL
2010-04-26 13:41:06 ----A---- C:\windows\system32\SSUBTMR6.DLL

======List of files/folders modified in the last 1 months======

2010-05-20 16:53:01 ----D---- C:\windows\Prefetch
2010-05-20 16:52:59 ----RD---- C:\Program Files
2010-05-20 16:52:33 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-05-20 16:15:22 ----D---- C:\windows\Temp
2010-05-20 15:31:54 ----AD---- C:\windows\system32
2010-05-19 12:31:30 ----A---- C:\windows\ModemLog_Nokia N97 Bluetooth Modem.txt
2010-05-19 08:41:30 ----D---- C:\windows\system32\CatRoot2
2010-05-19 08:39:56 ----A---- C:\windows\system32\log.txt
2010-05-19 08:37:51 ----A---- C:\windows\SchedLgU.Txt
2010-05-18 15:05:50 ----AD---- C:\WINDOWS
2010-05-18 08:48:50 ----A---- C:\windows\system.ini
2010-05-18 08:41:53 ----D---- C:\windows\system32\drivers
2010-05-18 08:41:52 ----D---- C:\windows\AppPatch
2010-05-18 08:41:34 ----D---- C:\Program Files\Fichiers communs
2010-05-18 08:36:40 ----D---- C:\QUARANTINE
2010-05-17 21:33:06 ----HD---- C:\windows\inf
2010-05-17 21:23:31 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\uTorrent
2010-05-17 20:35:51 ----SHD---- C:\windows\CSC
2010-05-17 17:37:47 ----SHD---- C:\windows\Installer
2010-05-17 10:32:07 ----D---- C:\Program Files\Internet Explorer
2010-05-17 10:26:10 ----D---- C:\windows\system32\CatRoot
2010-05-17 10:25:44 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-05-17 10:24:16 ----ASHD---- C:\windows\system32\dllcache
2010-05-17 10:24:12 ----D---- C:\windows\ie8updates
2010-05-17 10:16:53 ----RSD---- C:\windows\assembly
2010-05-17 10:12:36 ----D---- C:\windows\WinSxS
2010-05-17 08:37:32 ----ASH---- C:\boot.ini
2010-05-17 08:37:32 ----A---- C:\windows\win.ini
2010-05-17 08:33:07 ----D---- C:\windows\system32\fr-fr
2010-05-17 08:33:06 ----D---- C:\windows\Media
2010-05-17 08:33:05 ----D---- C:\windows\Help
2010-05-16 20:06:48 ----D---- C:\Program Files\Outlook Express
2010-05-16 20:02:50 ----D---- C:\windows\Debug
2010-05-16 20:00:14 ----HD---- C:\windows\$hf_mig$
2010-05-16 18:32:48 ----HD---- C:\Program Files\InstallShield Installation Information
2010-05-16 11:04:10 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-05-16 10:51:43 ----DC---- C:\windows\system32\DRVSTORE
2010-05-15 22:39:45 ----SHD---- C:\System Volume Information
2010-05-15 22:39:45 ----D---- C:\windows\system32\Restore
2010-05-15 11:57:02 ----D---- C:\windows\pss
2010-05-14 22:39:31 ----A---- C:\windows\system32\PerfStringBackup.INI
2010-05-14 22:32:16 ----D---- C:\UsbFix
2010-05-14 10:09:32 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\webex
2010-05-14 10:08:33 ----SD---- C:\windows\Downloaded Program Files
2010-05-13 19:10:38 ----D---- C:\windows\network diagnostic
2010-05-13 11:01:36 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\DivX
2010-05-13 10:19:11 ----D---- C:\Program Files\Fichiers communs\DivX Shared
2010-05-08 17:58:46 ----D---- C:\Program Files\IK Multimedia
2010-05-04 19:41:46 ----A---- C:\windows\demdata.txt
2010-05-03 22:07:43 ----RSD---- C:\windows\Fonts
2010-05-03 19:16:25 ----D---- C:\Documents and Settings\DMARTIANO\Application Data\Help
2010-04-30 11:51:08 ----A---- C:\windows\system32\MRT.exe
0
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\D:\Program Files\Avira\AntiVir Desktop\avgio.sys []
R1 avipbb;avipbb; C:\windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 IKSysFlt;System Filter Driver; C:\windows\system32\drivers\iksysflt.sys [2008-08-25 66952]
R1 IKSysSec;System Security Driver; C:\windows\system32\drivers\iksyssec.sys [2008-08-25 81288]
R1 intelppm;Pilote de processeur Intel; C:\windows\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
R1 mferkdk;VSCore mferkdk; \??\C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys []
R1 mfetdik;McAfee Inc.; C:\windows\system32\drivers\mfetdik.sys [2006-11-30 52136]
R1 ssmdrv;ssmdrv; C:\windows\system32\DRIVERS\ssmdrv.sys [2010-05-15 28520]
R1 TPHKDRV;TPHKDRV; C:\windows\system32\DRIVERS\TPHKDRV.sys [2008-05-12 17844]
R1 TPPWRIF;TPPWRIF; C:\windows\System32\drivers\Tppwrif.sys [2009-03-23 4442]
R1 truecrypt;truecrypt; C:\windows\System32\drivers\truecrypt.sys [2009-12-22 223440]
R1 TSMAPIP;TSMAPIP; C:\windows\System32\drivers\TSMAPIP.SYS [2009-01-07 4608]
R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI; C:\windows\system32\DRIVERS\wmiacpi.sys [2008-04-13 8832]
R2 avgntflt;avgntflt; C:\windows\system32\DRIVERS\avgntflt.sys [2010-05-15 56816]
R2 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\windows\system32\Drivers\CVPNDRVA.sys []
R2 pmem;pmem; \??\C:\WINDOWS\System32\drivers\pmemnt.sys []
R2 s24trans;Transport RLAN; C:\windows\system32\DRIVERS\s24trans.sys [2008-08-13 11904]
R3 5U875UVC;Integrated Camera; C:\windows\system32\DRIVERS\5U875.sys [2008-09-03 72192]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver; C:\windows\System32\Drivers\ATSwpWDF.sys [2009-03-19 482176]
R3 btaudio;Périphérique audio Bluetooth; C:\windows\system32\drivers\btaudio.sys [2008-03-10 534312]
R3 BTDriver;Pilote de communications virtuelles Bluetooth; C:\windows\system32\DRIVERS\btport.sys [2008-02-04 37160]
R3 BTKRNL;Enumérateur de bus Bluetooth; C:\windows\system32\DRIVERS\btkrnl.sys [2008-03-27 990632]
R3 BTWDNDIS;Serveur d'accès au réseau local Bluetooth; C:\windows\system32\DRIVERS\btwdndis.sys [2007-09-20 156392]
R3 btwmodem;Modem Bluetooth; C:\windows\system32\DRIVERS\btwmodem.sys [2008-02-04 37032]
R3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\windows\System32\Drivers\btwusb.sys [2008-03-27 47272]
R3 CmBatt;Pilote d'adaptateur secteur Microsoft; C:\windows\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service; C:\windows\system32\drivers\CHDAU32.sys [2009-10-06 814592]
R3 DNE;Deterministic Network Enhancer Miniport; C:\windows\system32\DRIVERS\dne2000.sys [2007-01-31 127376]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver; C:\windows\system32\DRIVERS\e1y5132.sys [2009-03-27 239760]
R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HECI;Intel(R) Management Engine Interface; C:\windows\system32\DRIVERS\HECI.sys [2008-03-26 40832]
R3 ialm;ialm; C:\windows\system32\DRIVERS\igxpmp32.sys [2008-10-21 6048480]
R3 IBMPMDRV;IBMPMDRV; C:\windows\system32\DRIVERS\ibmpmdrv.sys [2008-02-20 22696]
R3 mfeapfk;McAfee Inc.; C:\windows\system32\drivers\mfeapfk.sys [2006-11-30 64360]
R3 mfeavfk;McAfee Inc.; C:\windows\system32\drivers\mfeavfk.sys [2006-11-30 72264]
R3 mfebopk;McAfee Inc.; C:\windows\system32\drivers\mfebopk.sys [2006-11-30 34152]
R3 mfehidk;McAfee Inc.; C:\windows\system32\drivers\mfehidk.sys [2006-11-30 168776]
R3 NETw5x32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit; C:\windows\system32\DRIVERS\NETw5x32.sys [2009-03-04 4202496]
R3 psadd;Lenovo Parties Service Access Device Driver; C:\windows\system32\DRIVERS\psadd.sys [2008-09-25 31680]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\windows\System32\Drivers\RootMdm.sys [2004-08-05 5888]
R3 Tp4Track;PS/2 TrackPoint Driver; C:\windows\system32\DRIVERS\tp4track.sys [2009-01-26 23080]
R3 tpm;tpm; C:\windows\system32\DRIVERS\tpm.sys [2008-03-26 13824]
R3 TVTI2C;Lenovo SM bus driver; C:\windows\system32\DRIVERS\Tvti2c.sys [2008-02-22 37312]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\windows\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\windows\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\windows\System32\Drivers\wdf01000.sys [2007-09-15 501800]
S1 kbdhid;Pilote HID de clavier; C:\windows\system32\DRIVERS\kbdhid.sys [2008-04-13 14720]
S1 MpKsl22f1781c;MpKsl22f1781c; \??\C:\Program Files\Windows Live Safety Center\MpKsl22f1781c.sys []
S2 mdmxsdk;mdmxsdk; C:\windows\system32\DRIVERS\mdmxsdk.sys []
S2 rimmptsk;rimmptsk; C:\windows\system32\DRIVERS\rimmptsk.sys [2008-02-15 46592]
S2 rimsptsk;rimsptsk; C:\windows\system32\DRIVERS\rimsptsk.sys [2007-07-30 43008]
S2 rismxdp;Ricoh xD-Picture Card Driver; C:\windows\system32\DRIVERS\rixdptsk.sys [2007-07-30 38400]
S3 ac97intc;Service d'installation du pilote audio Intel(r) 82801 (WDM); C:\windows\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 ApfiltrService;Alps Pointing-device Filter Driver; C:\windows\system32\DRIVERS\Apfiltr.sys [2008-03-07 154672]
S3 Arp1394;Protocole client ARP 1394; C:\windows\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\windows\system32\DRIVERS\b57xp32.sys [2007-11-29 163328]
S3 BrScnUsb;Brother USB Still Image driver; C:\windows\System32\Drivers\BrScnUsb.sys [2003-12-19 15263]
S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver; C:\windows\System32\Drivers\BrSerIf.sys [2004-06-12 51712]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver; C:\windows\System32\Drivers\BrUsbSer.sys [2004-01-10 11648]
S3 catchme;catchme; \??\C:\DOCUME~1\DMARTI~1\LOCALS~1\Temp\catchme.sys []
S3 CCDECODE;Décodeur sous-titre fermé; C:\windows\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 cpuz132;cpuz132; \??\C:\windows\TEMP\cpuz132\cpuz132_x32.sys []
S3 CVirtA;Cisco Systems VPN Adapter; C:\windows\system32\DRIVERS\CVirtA.sys [2007-01-18 5275]
S3 DBGMSG;DBGMSG; dbgmsg.sys []
S3 dot4;Pilote MS IEEE-1284.4; C:\windows\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Pilote de classe Imprimante pour IEEE-1284.4; C:\windows\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 dot4usb;Filtre Dot4USB Dot4USB Filter; C:\windows\system32\DRIVERS\dot4usb.sys [2001-08-23 24064]
S3 E100B;Pilote de carte Intel (R) PRO; C:\windows\system32\DRIVERS\e100b325.sys [2001-08-23 117760]
S3 G400;G400; C:\windows\system32\DRIVERS\G400m.sys [2001-08-23 322560]
S3 HidUsb;Pilote de classe HID Microsoft; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 lnvobus;Ericsson F3507g Mobile Broadband Minicard Composite Device driver (WDM); C:\windows\system32\DRIVERS\lnvobus.sys []
S3 lnvocard;Ericsson F3507g Mobile Broadband Minicard Device Management; C:\windows\system32\DRIVERS\lnvocard.sys []
S3 lnvogps;Ericsson F3507g Mobile Broadband Minicard GPS Port; C:\windows\system32\DRIVERS\lnvogps.sys []
S3 lnvomdfl;Ericsson F3507g Mobile Broadband Minicard Modem Filter; C:\windows\system32\DRIVERS\lnvomdfl.sys []
S3 lnvomdfl2;Ericsson F3507g Mobile Broadband Minicard Data Modem Filter; C:\windows\system32\DRIVERS\lnvomdfl2.sys []
S3 lnvomdm;Ericsson F3507g Mobile Broadband Minicard Modem Driver; C:\windows\system32\DRIVERS\lnvomdm.sys []
S3 lnvomdm2;Ericsson F3507g Mobile Broadband Minicard Data Modem; C:\windows\system32\DRIVERS\lnvomdm2.sys []
S3 lnvond5;Ericsson F3507g Mobile Broadband Minicard Network Adapter (NDIS); C:\windows\system32\DRIVERS\lnvond5.sys []
S3 lnvounic;Ericsson F3507g Mobile Broadband Minicard Network Adapter (WDM); C:\windows\system32\DRIVERS\lnvounic.sys []
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\windows\system32\drivers\mbamswissarmy.sys []
S3 mosuport;USB Serial/Parallel Ports; C:\windows\system32\DRIVERS\mosuport.sys [2006-05-05 855040]
S3 mouhid;Pilote HID de souris; C:\windows\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\windows\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\windows\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\windows\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;Pilote réseau 1394; C:\windows\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 nmwcd;Nokia USB Phone Parent; C:\windows\system32\drivers\ccdcmb.sys [2010-01-21 18048]
S3 nmwcdc;Nokia USB Generic; C:\windows\system32\drivers\ccdcmbo.sys [2009-12-30 22016]
S3 nv;nv; C:\windows\system32\DRIVERS\nv4_mini.sys [2004-08-04 1897408]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\windows\system32\DRIVERS\pccsmcfd.sys [2008-08-26 18816]
S3 rk_remover-boot;rk_remover-boot; \??\C:\windows\system32\drivers\rk_remover.sys []
S3 sdbus;sdbus; C:\windows\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 SLIP;Détrameur décalage BDA; C:\windows\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\windows\system32\DRIVERS\snp2uvc.sys [2007-02-16 9598080]
S3 Sony_EricssonWWSC;Ericsson F3507g Mobile Broadband Minicard PC SC Port; C:\windows\system32\DRIVERS\lnvoscard.sys []
S3 streamip;BDA IPSink; C:\windows\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 TwoTrack;Pilote de filtre de TrackPoint IBM PS/2; C:\windows\system32\DRIVERS\TwoTrack.sys [2001-08-17 11520]
S3 upperdev;upperdev; C:\windows\system32\DRIVERS\usbser_lowerflt.sys [2009-12-30 7936]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;Pilote de scanneur USB; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbser;USB Modem Driver; C:\windows\system32\drivers\usbser.sys [2008-04-13 26112]
S3 UsbserFilt;UsbserFilt; C:\windows\system32\DRIVERS\usbser_lowerfltj.sys [2009-12-30 7936]
S3 USBSTOR;Pilote de stockage de masse USB; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 usbvideo;Périphérique vidéo USB (WDM); C:\windows\System32\Drivers\usbvideo.sys [2008-04-13 121984]
S3 vsdatant;vsdatant; \??\C:\windows\system32\vsdatant.sys []
S3 WpdUsb;WpdUsb; C:\windows\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;Codec Teletext standard; C:\windows\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]
S4 agp440;Filtre de bus AGP Intel; C:\windows\system32\DRIVERS\agp440.sys [2008-04-13 42368]
S4 agpCPQ;Filtre de bus AGP Compaq; C:\windows\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
S4 alim1541;Filtre de bus AGP ALI; C:\windows\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
S4 amdagp;Pilote de filtre du bus AMD AGP; C:\windows\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
S4 cbidf;cbidf; C:\windows\system32\DRIVERS\cbidf2k.sys [2001-08-18 13952]
S4 IntelIde;IntelIde; C:\windows\system32\DRIVERS\intelide.sys [2008-04-13 5504]
S4 sisagp;Filtre de bus AGP SIS; C:\windows\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
S4 sptd;sptd; C:\windows\System32\Drivers\sptd.sys [2010-04-01 691696]
S4 viaagp;Filtre de bus AGP VIA; C:\windows\system32\DRIVERS\viaagp.sys [2008-04-13 42240]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Planificateur; D:\Program Files\Avira\AntiVir Desktop\sched.exe [2010-05-15 108289]
R2 AntiVirService;Avira AntiVir Guard; D:\Program Files\Avira\AntiVir Desktop\avguard.exe [2010-05-15 185089]
R2 ATService;AuthenTec Fingerprint Service; C:\WINDOWS\system32\AtService.exe [2009-03-19 1680632]
R2 Brother XP spl Service;BrSplService; C:\windows\system32\brsvc01a.exe [2002-04-12 57344]
R2 Browser Defender Update Service;Browser Defender Update Service; C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
R2 btwdins;Bluetooth Service; C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe [2008-03-28 342624]
R2 dtsvc;Data Transfer Service; C:\WINDOWS\system32\DTS.exe [2009-03-19 98304]
R2 EpsonBidirectionalService;EpsonBidirectionalService; C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe [2006-12-19 94208]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2009-02-27 870672]
R2 IBMPMSVC;ThinkPad PM Service; C:\windows\system32\ibmpmsvc.exe [2008-02-20 36128]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 LMS;Intel(R) Active Management Technology Local Management Service; C:\Program Files\Intel\AMT\LMS.exe [2009-02-12 174616]
R2 McAfeeFramework;McAfee Framework Service; C:\Program Files\McAfee\Common Framework\FrameworkService.exe [2006-11-17 104000]
R2 McShield;McAfee McShield; C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe [2006-11-30 144960]
R2 McTaskManager;McAfee Task Manager; C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [2006-11-30 54872]
R2 Power Manager DBC Service;Power Manager DBC Service; C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE [2009-03-23 53248]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe [2009-02-27 473360]
R2 S24EventMonitor;Intel(R) PROSet/Wireless WiFi Service; C:\Program Files\Intel\WiFi\bin\S24EvMon.exe [2009-02-27 909312]
R2 TPHDEXLGSVC;ThinkPad HDD APS Logging Service; C:\windows\System32\TPHDEXLG.exe [2009-01-28 39976]
R2 UNS;Intel(R) Active Management Technology User Notification Service; C:\Program Files\Fichiers communs\Intel\Privacy Icon\UNS\UNS.exe [2009-02-12 2058776]
R3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2010-01-26 652800]
R3 WSearch;Windows Search; C:\windows\system32\SearchIndexer.exe [2008-05-26 439808]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe [2007-10-26 1524512]
S3 FingerprintServer;Fingerprint Server; C:\WINDOWS\system32\FpLogonServ.exe [2009-03-19 118784]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2007-02-10 29178224]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SQLWriter;Enregistreur VSS SQL Server; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
S4 ADMonitor;AD Monitor; C:\WINDOWS\system32\ADMonitor.exe [2009-03-19 106496]
S4 aspnet_state;Service d'état ASP.NET; C:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-09-17 153376]
S4 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
S4 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
S4 NetTcpPortSharing;Service de partage de ports Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 ProtexisLicensing;ProtexisLicensing; C:\windows\system32\PSIService.exe [2007-06-05 177704]
S4 RoxMediaDB10;RoxMediaDB10; C:\Program Files\Fichiers communs\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2008-04-25 1120752]
S4 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2009-09-23 358600]
S4 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2009-09-23 1141200]
S4 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2007-02-10 242544]
S4 StarWindServiceAE;StarWind AE Service; D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-23 370688]
S4 stllssvr;stllssvr; C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S4 SUService;System Update; c:\program files\lenovo\system update\suservice.exe [2009-05-15 28672]
S4 ThinkVantage Registry Monitor Service;ThinkVantage Registry Monitor Service; c:\Program Files\Fichiers communs\Lenovo\tvt_reg_monitor_svc.exe [2008-06-13 746808]
S4 TpKmpSVC;IBM KCU Service; C:\windows\system32\TpKmpSVC.exe [2006-06-29 32768]
S4 TSSCoreService;TSS Core Service; C:\Program Files\Lenovo\Client Security Solution\tvttcsd.exe [2008-06-13 779576]
S4 TVT Scheduler;TVT Scheduler; c:\Program Files\Fichiers communs\Lenovo\Scheduler\tvtsched.exe [2008-11-24 1155072]
S4 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe []
S4 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-13 14336]

-----------------EOF-----------------

Le COMBOFIX est en cours de préparation ;-)
Merci à vous
0
ComboFix 10-05-15.01 - DIANO 20/05/2010 17:31:00.3.2 - x86
Lancé depuis: c:\documents and settings\DIANO\Bureau\Outils\CLEAN\combofix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Un antivirus résident est actif

.

((((((((((((((((((((((((((((( Fichiers créés du 2010-04-20 au 2010-05-20 ))))))))))))))))))))))))))))))))))))
.

2010-05-20 14:52 . 2010-05-20 14:53 -------- d-----w- c:\program files\trend micro
2010-05-19 06:30 . 2010-05-19 06:30 -------- d-----r- c:\documents and settings\NetworkService\Mes documents
2010-05-17 08:16 . 2010-05-17 08:16 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\PCHealth
2010-05-17 06:28 . 2010-05-17 06:31 -------- dc-h--w- c:\windows\ie8
2010-05-16 17:57 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-05-15 17:01 . 2010-05-15 17:54 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-05-15 17:01 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-05-15 17:01 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-05-15 17:01 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-05-15 17:01 . 2010-05-15 17:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-05-15 05:01 . 2010-05-15 20:07 52736 ----a-w- c:\windows\system32\drivers\rk_remover.sys
2010-05-15 04:42 . 2010-05-15 04:42 -------- d-----w- c:\documents and settings\DIANO\Application Data\Malwarebytes
2010-05-15 04:42 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-15 04:42 . 2010-05-15 04:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-15 04:42 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-15 04:42 . 2010-05-15 04:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-15 04:27 . 2010-05-15 04:31 -------- d-----w- c:\program files\ZHPDiag
2010-05-14 20:51 . 2010-05-06 08:36 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-14 12:52 . 2010-05-19 06:29 -------- d-----w- c:\documents and settings\NetworkService\Bureau
2010-05-14 07:17 . 2010-05-14 07:17 -------- d-----w- c:\documents and settings\LocalService\Bureau
2010-05-14 06:18 . 2010-05-16 08:51 -------- d-----w- c:\program files\Lavasoft
2010-05-14 06:18 . 2010-05-14 06:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-05-14 05:51 . 2010-05-17 19:33 -------- d-----w- c:\program files\Windows Live Safety Center
2010-05-13 21:53 . 2009-09-29 13:14 3101560 ----a-w- c:\documents and settings\DIANO\Application Data\Simply Super Software\Trojan Remover\suf213.exe
2010-05-13 21:47 . 2006-06-19 11:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-05-13 21:47 . 2006-05-25 13:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-05-13 21:47 . 2005-08-25 23:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-05-13 21:47 . 2003-02-02 18:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2010-05-13 21:47 . 2002-03-05 23:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2010-05-13 21:47 . 2010-05-13 21:47 -------- d-----w- c:\documents and settings\DIANO\Application Data\Simply Super Software
2010-05-13 21:47 . 2010-05-13 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2010-05-13 21:22 . 2010-05-13 21:52 -------- d-----w- C:\rsit
2010-05-13 18:21 . 2010-05-17 06:32 -------- d--h--w- c:\windows\msdownld.tmp
2010-05-13 17:07 . 2010-05-13 18:15 -------- d-----w- c:\windows\SoftwareDistribution.old
2010-05-13 13:36 . 2010-05-13 13:36 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\Threat Expert
2010-05-13 13:26 . 2010-01-21 23:21 165840 ----a-w- c:\windows\PCTBDRes.dll
2010-05-13 13:26 . 2010-01-21 23:21 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-05-13 13:26 . 2010-01-21 23:21 1152444 ----a-w- c:\windows\UDB.zip
2010-05-13 13:26 . 2010-01-21 23:21 1652688 ----a-w- c:\windows\PCTBDCore.dll
2010-05-13 13:26 . 2010-01-21 23:21 767952 ----a-w- c:\windows\BDTSupport.dll
2010-05-13 13:26 . 2008-11-26 10:08 131 ----a-w- c:\windows\IDB.zip
2010-05-13 13:14 . 2009-09-24 06:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-05-13 13:14 . 2009-10-06 14:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-05-13 13:14 . 2009-09-23 14:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-05-13 13:13 . 2009-09-03 07:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-05-13 13:13 . 2010-05-15 16:22 -------- d-----w- c:\program files\Spyware Doctor
2010-05-13 13:13 . 2010-05-13 13:26 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2010-05-13 13:13 . 2010-05-13 13:13 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-05-13 09:00 . 2010-05-13 09:00 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-13 08:20 . 2010-05-13 08:05 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-05-13 08:20 . 2010-05-13 08:05 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-05-13 08:20 . 2009-11-13 16:42 529171 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Player\DivXPlayerUninstall.exe
2010-05-13 08:20 . 2010-05-13 08:20 56766 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-05-13 08:20 . 2009-11-13 16:42 529171 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Plus DirectShow Filters\DivXDSFiltersUninstall.exe
2010-05-13 08:20 . 2009-11-13 16:42 529171 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe
2010-05-13 08:20 . 2010-05-13 08:20 56978 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-05-13 08:20 . 2010-05-13 08:20 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-05-13 08:20 . 2010-05-13 08:20 57679 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-05-13 08:20 . 2010-05-13 08:20 84040 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-05-13 08:13 . 2010-05-13 21:55 -------- d-----w- c:\program files\DivX
2010-05-13 08:05 . 2010-05-13 08:05 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-13 08:05 . 2010-05-13 08:20 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-05-12 05:22 . 2010-05-12 05:22 3532 ----a-w- C:\drmHeader.bin
2010-05-04 21:03 . 2010-05-04 21:03 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\GPSENABLER
2010-05-03 20:07 . 2010-05-03 20:07 -------- d-----w- c:\program files\Rallentando Software
2010-05-03 17:16 . 2010-05-03 17:16 7168 ----a-w- c:\documents and settings\DIANO\Application Data\Thinstall\MidiIllustrator v2.01\10000004b00002i\winhlp32.exe
2010-05-03 17:08 . 2010-05-03 17:08 -------- d-----w- c:\documents and settings\DIANO\Application Data\Music Recognition
2010-04-30 16:46 . 2010-04-30 16:46 -------- d-----w- c:\documents and settings\DIANO\Application Data\Thinstall
2010-04-27 22:45 . 2010-04-27 23:00 3 ----a-w- c:\windows\system32\mnprxp1.bin
2010-04-27 22:39 . 2010-04-27 22:39 737280 ----a-w- c:\windows\iun6002.exe
2010-04-27 20:25 . 2010-04-27 20:33 -------- d-----w- c:\documents and settings\DIANO\Application Data\REAPER
2010-04-27 20:08 . 1998-02-06 19:37 299520 ----a-w- c:\windows\uninst.exe
2010-04-27 20:07 . 2010-04-27 20:07 -------- d-----w- c:\documents and settings\DIANO\WINDOWS
2010-04-26 14:26 . 2010-04-26 14:26 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\Yamaha Corporation
2010-04-26 14:24 . 2010-04-26 14:24 -------- d-----w- c:\program files\Yamaha Corporation
2010-04-26 14:24 . 2010-04-26 14:24 -------- d-----w- c:\documents and settings\DIANO\Local Settings\Application Data\Downloaded Installations
2010-04-26 11:41 . 1997-07-31 21:08 34816 ----a-w- c:\windows\system32\VBHLP32.DLL
2010-04-26 11:41 . 2009-02-19 12:15 208896 ----a-w- c:\windows\system32\VBALNCSM6.DLL
2010-04-26 11:41 . 2003-01-26 11:41 40960 ----a-w- c:\windows\system32\SSUBTMR6.DLL

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-20 15:33 . 2009-12-06 17:31 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-17 19:23 . 2009-11-11 19:12 -------- d-----w- c:\documents and settings\DIANO\Application Data\uTorrent
2010-05-17 08:25 . 2009-03-26 07:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-05-16 16:32 . 2009-03-26 06:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-15 20:37 . 2004-08-03 22:59 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-05-15 20:06 . 2010-05-15 20:06 96512 ----a-w- c:\windows\system32\drivers\tsk7.tmp
2010-05-14 20:39 . 2006-01-26 20:35 599052 ----a-w- c:\windows\system32\perfh00C.dat
2010-05-14 20:39 . 2006-01-26 20:35 120956 ----a-w- c:\windows\system32\perfc00C.dat
2010-05-14 08:09 . 2009-11-20 13:42 -------- d-----w- c:\documents and settings\DIANO\Application Data\webex
2010-05-13 09:01 . 2009-11-13 16:43 -------- d-----w- c:\documents and settings\DIANO\Application Data\DivX
2010-05-08 15:58 . 2010-04-01 20:20 -------- d-----w- c:\program files\IK Multimedia
2010-05-08 15:56 . 2010-04-01 20:28 16 ----a-w- c:\windows\msocreg32.dat
2010-05-04 20:22 . 2009-11-11 18:51 1234416 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-04-08 18:49 . 2010-01-15 15:34 -------- d-----w- c:\documents and settings\DIANO\Application Data\gtk-2.0
2010-04-06 07:11 . 2010-04-06 07:11 -------- d-----w- c:\documents and settings\DIANO\Application Data\Plogue
2010-04-05 21:07 . 2010-04-05 21:07 -------- d-----w- c:\documents and settings\DIANO\Application Data\Garritan
2010-04-05 21:06 . 2010-04-05 21:06 -------- d-----w- c:\program files\Plogue
2010-04-05 16:01 . 2010-04-01 18:12 21840 ----atw- c:\windows\system32\SIntfNT.dll
2010-04-05 16:01 . 2010-04-01 18:12 17212 ----atw- c:\windows\system32\SIntf32.dll
2010-04-05 16:01 . 2010-04-01 18:12 12067 ----atw- c:\windows\system32\SIntf16.dll
2010-04-02 17:04 . 2010-04-02 17:04 -------- d-----w- c:\documents and settings\DIANO\Application Data\Apple Computer
2010-04-02 12:05 . 2009-11-28 21:45 2880 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-04-02 06:47 . 2010-04-02 06:47 -------- d-----w- c:\documents and settings\All Users\Application Data\QuickTime
2010-04-01 20:24 . 2010-04-01 20:24 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-04-01 20:24 . 2010-04-01 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-04-01 20:24 . 2010-04-01 20:24 -------- d-----w- c:\program files\Apple Software Update
2010-04-01 20:24 . 2010-04-01 20:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-04-01 18:10 . 2010-04-01 18:10 -------- d-----w- c:\program files\Borland
2010-04-01 18:08 . 2009-11-09 16:52 -------- d-----w- c:\documents and settings\DIANO\Application Data\Roxio
2010-04-01 18:04 . 2010-04-01 18:04 -------- d-----w- c:\program files\Fichiers communs\PCSuite
2010-04-01 18:04 . 2009-11-10 16:16 -------- d-----w- c:\program files\Fichiers communs\Nokia
2010-04-01 18:02 . 2010-04-01 18:02 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\pcswpcsi.exe
2010-04-01 18:02 . 2010-04-01 18:02 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-04-01 18:02 . 2010-04-01 18:02 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstCCD.exe
2010-04-01 18:02 . 2010-04-01 18:02 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Installer\CommonCustomActions\UninstPCS.exe
2010-04-01 18:02 . 2009-11-10 15:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2010-04-01 18:02 . 2010-04-01 18:03 34503960 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{19DC9559-9C20-4A46-A67D-7ECBA52A2788}\Nokia_PC_Suite_fre.exe
2010-04-01 17:49 . 2010-04-01 17:49 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-04-01 16:18 . 2010-04-01 13:43 -------- d-----w- c:\program files\Fichiers communs\Native Instruments
2010-04-01 13:44 . 2010-04-01 13:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Native Instruments
2010-03-31 01:58 . 2008-04-08 18:31 125424 ------w- c:\windows\system32\pxinsi64.exe
2010-03-31 01:58 . 2007-12-13 13:49 133616 ------w- c:\windows\system32\PxAFS.DLL
2010-03-30 14:49 . 2010-03-30 14:49 -------- d-----w- c:\program files\Fichiers communs\L&H
2010-03-30 14:23 . 2010-03-30 14:23 -------- d-----w- c:\program files\NCT
2010-03-30 14:23 . 2009-06-29 20:12 -------- d-----w- c:\program files\Common Files
2010-03-24 05:52 . 2009-11-10 16:17 -------- d-----w- c:\documents and settings\DIANO\Application Data\Nokia
2010-03-16 14:49 . 2010-03-16 14:49 3351812 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}\Installer\CommonCustomActions\msxml6Exec.exe
2010-03-16 14:49 . 2010-03-16 14:49 36864 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}\Installer\CommonCustomActions\Sleep.exe
2010-03-16 14:49 . 2010-03-16 14:49 3203453 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}\Installer\CommonCustomActions\vcredistExec.exe
2010-03-16 14:49 . 2010-03-16 14:51 34679832 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{D8DDC00B-2881-407D-AAC2-44AEE70AF0B7}\NokiaSoftwareUpdaterSetup_fr[1].exe
2010-03-10 06:16 . 2006-01-26 20:35 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 17:59 . 2010-03-08 17:59 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-02-25 06:17 . 2006-01-26 20:35 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2006-01-26 20:34 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 19:27 . 2010-02-19 19:27 720384 ----a-w- c:\windows\system32\DivX.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2010-02-19 19:27 . 2010-02-19 19:27 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2010-02-19 19:27 . 2010-02-19 19:27 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2010-02-19 19:27 . 2010-02-19 19:27 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2010-02-19 19:27 . 2010-02-19 19:27 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-28 21:49 . 2009-11-28 21:49 88 --sh--r- c:\windows\system32\C759283878.sys
.


.
0